Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Keycloak admin user cannot see groups for cluster members #45496

Open
samjustus opened this issue May 15, 2024 · 1 comment
Open

[BUG] Keycloak admin user cannot see groups for cluster members #45496

samjustus opened this issue May 15, 2024 · 1 comment
Labels
area/rbac kind/bug Issues that are defects reported by users or that we know have reached a real release priority/1 team/collie the team that is responsible for auth and rbac within rancher
Milestone

Comments

@samjustus
Copy link
Collaborator

Issue description:
An admin user can see only groups to which it belongs on keycloak. So in the Rancher scope, the admin cannot see groups assigned to a cluster, or that someone added to an administrator role.

Business impact:
One cannot see groups someone else may have assigned to the administrator role. This can result in permissions that are not desired, and this problem cannot be detected.

Repro steps:

add a group to a Cluster -> Cluster Members
log in with an administrator that does not belong to that group
You get Unable to fetch principal info
Workaround:
Is a workaround available and implemented? no
What is the workaround:

Actual behavior:
Administrators cannot see groups assigned to cluster memberships unless they are part of that group on keycloak

Expected behavior:
Administrators should be able to see groups assigned to clusters

@samjustus samjustus added the kind/bug Issues that are defects reported by users or that we know have reached a real release label May 15, 2024
@samjustus
Copy link
Collaborator Author

SURE-6002

@samjustus samjustus added priority/1 area/rbac team/collie the team that is responsible for auth and rbac within rancher labels May 15, 2024
@samjustus samjustus added this to the v2.10-Next1 milestone May 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/rbac kind/bug Issues that are defects reported by users or that we know have reached a real release priority/1 team/collie the team that is responsible for auth and rbac within rancher
Projects
None yet
Development

No branches or pull requests

1 participant